Instagram API Access Blocked? Causes and Fixes by Error
Instagram API access usually gets blocked for one of eight reasons: Meta restricted or disabled the app, a permission lacks Advanced Access, Business Verification is missing, the annual data access renewal lapsed, a token expired or was revoked, the account isn't Business or Creator, Instagram restricted the account, or a rate limit hit. The error code tells you which. Adeli owns the Meta app, review, and token refresh.
When your Instagram API access is blocked, the cause is almost always one of eight things: Meta restricted or disabled your app, a permission lacks Advanced Access, Business Verification is missing, your annual data access renewal lapsed, a token expired or was revoked, the account isn't a Business or Creator account, Instagram restricted the account itself, or you hit a rate limit. Each one returns a different error code, so start with the code, then apply the fix for that cause.
App review and token basics have their own posts: how long Meta app review takes and the Instagram API guide.
Why is my Instagram API access blocked?#
Most blocks come from Meta's rules, and they fall into three groups:
- App-level blocks. Meta has restricted or deactivated the app, the app only has Standard Access, Business Verification isn't done, or the data access renewal deadline passed. These hit every connected account at once.
- Account-level blocks. One user's token expired or was revoked, the account is personal rather than professional, or Instagram restricted that account. These hit one account at a time.
- Throttling. The app, a user, or an Instagram account went over a rate limit or the daily publishing cap. These clear on their own after a wait.
Start by checking whether every account fails or only one. If all of them fail, look at the app. If one fails, look at that account and its token.
How do I tell which block I hit?#
Read the code and error_subcode fields in the error response. The table maps the codes Meta documents to their causes and fixes. Sources: Meta's Graph API error handling, Instagram error codes, and rate limiting docs.
| Error or symptom | Likely cause | Fix |
|---|---|---|
| Code 190, or subcodes 458, 460, 463, 467 | Token expired, invalid, password changed, or the user removed your app | Have the user log in again; refresh tokens before expiry |
| Code 10 or 200–299 | Missing permission, or the permission lacks Advanced Access | Request the permission; get Advanced Access through App Review |
| Other businesses can't grant permissions, and features are inactive | Business Verification not complete | Verify the business connected to the app |
| Code 24 / 2207006 or 36001 / 2207005 | Missing permission or expired token (Instagram) | Check the token's scopes, then reconnect the account |
| Code 25 / 2207050 | "The Instagram account is restricted" | The account owner resolves it in Instagram |
| Code 4 / 2207051 | Instagram flagged the activity as possible spam | Slow down and retry later |
| Code 368 | Temporarily blocked for policy violations | Wait, then fix the behavior that triggered it |
| Code 4, 17, or 80002 | App, user, or Instagram rate limit reached | Back off; read the usage headers |
| Code 9 / 2207042 | 100-post daily publishing cap reached | Wait for the rolling 24-hour window |
| Every call fails, plus an email or developer alert from Meta | App restricted or deactivated by enforcement | Fix the violation, then appeal |
| Every call fails after a renewal notice went unanswered | Data access renewal deadline missed | Complete the renewal in the App Dashboard |
If you're stuck on the app-level rows, Adeli's Instagram API moves them off your plate: Adeli holds the Meta developer app and goes through its review.
Is my Meta app restricted or disabled?#
If every account fails at once and Meta has emailed you, the app has probably been enforced on. It's the most serious kind of Meta API access block. Meta's enforcement page lists the actions it can take for a Platform Terms or Developer Policies violation:
- A warning, sometimes with a deadline to fix the issue.
- A temporary restriction on certain actions, such as posting content.
- Revoked permissions and features.
- Deactivation and removal of the app.
- Deactivation and deletion of the developer account.
Meta notifies you in two places: the contact email in your app's Settings > Basic panel, and the developer alerts inbox. Meta says developer alerts have to be turned on in your developer settings, so check that they are.
To fix it:
- Read the violation. The developer appeals page lists every app Meta has enforced on and the terms or policies it says you broke.
- Fix the behavior. Meta says you may need to debug your app, update its integration, or stop the behavior that isn't compliant.
- Appeal. Submit the appeal from the appeals page. If you got a warning, you can ask for an extension by replying to the warning email from the app's contact email address.
Why can only my own accounts connect?#
Your permissions probably have Standard Access only. Meta's access levels doc says Standard Access permissions "can only be requested from app users who have a role on the requesting app." Your own test accounts work. Your customers' accounts don't.
The fix is Advanced Access, which requires Business Verification and, for most Instagram permissions, App Review. That's the step people search as "Instagram API approval." There's no separate Instagram process: every permission, such as instagram_business_content_publish, goes through Meta App Review. Our post on how long Meta app review takes covers the timeline and the rejections to expect.
Does missing Business Verification block API access?#
Yes, for any app that serves other businesses. Meta's Business Verification doc says apps that request Advanced Access, or let other businesses access their own data, must be connected to a verified business. Until then, "app users from other Businesses will be unable to grant these apps permissions and all features will be inactive."
To fix it, go to Settings > Basic > Verification in the App Dashboard and select Start Verification. An admin of the business finishes the process in Business Manager.
Did my data use checkup or annual renewal lapse?#
If you ignored a renewal notice, your app may be deactivated. Meta's Data Use Checkup is an annual certification that your use of Meta APIs still complies with its terms. Meta is folding it into a single data access renewal, together with data handling questions, App Review, and the Data Protection Assessment.
The rules from Meta's data access renewal FAQ:
- The deadline is 60 calendar days from the first notification.
- Missing it deactivates the app "until data access renewal is completed."
- Extensions will not be provided.
To fix it, complete the renewal from the App Dashboard. In the Data Use Checkup doc, that means reviewing your approved permissions, certifying compliance, answering data handling questions, and giving testing instructions.
Why did a working Instagram access token stop working?#
The token expired or was invalidated, and error code 190 tells you so. Meta's subcodes narrow it down:
| Subcode | Meaning | What the user does |
|---|---|---|
| 458 | App not installed (the user removed your app) | Reconnect |
| 460 | Password changed | Log in again |
| 463 | Expired | Log in again |
| 467 | Invalid access token | Log in again |
Long-lived Instagram Login tokens last 60 days, and a token nobody refreshes is gone for good. Run a refresh job for every connected account. A 190 on one account means that user has to reconnect; your other accounts keep working. The Instagram API guide walks through the refresh call. For Facebook Login tokens, the debug_token endpoint shows whether a token is valid, when it expires, and which scopes it carries.
Why won't the Instagram account itself work?#
The account is either the wrong type or restricted by Instagram.
- Personal accounts never work. The Instagram API only supports Business and Creator accounts. The user can switch to a professional account for free, then reconnect.
- Facebook Login needs a linked Page. If you build with Facebook Login, the professional account also has to be linked to a Facebook Page the user manages.
- Restricted accounts return code 25 / 2207050. Meta describes this as an inactive or checkpointed account. Your app can't fix it; the owner has to clear it inside Instagram.
- Spam flags return code 4 / 2207051. Meta's message reads "We restrict certain activity to protect our community."
Am I being rate limited?#
Codes 4, 17, 80002, and 9 / 2207042 mean throttling, which lifts after a wait. Meta's rate limiting doc separates them:
| Code | Limit hit |
|---|---|
| 4 | The app's platform rate limit |
| 17 | One user's rate limit |
| 80002 | Instagram's business use case limit: 4,800 × the account's impressions per 24 hours |
| 9 / 2207042 | 100 API-published posts per account per rolling 24 hours |
Read the headers before you retry. X-App-Usage shows the app's usage as percentages. X-Business-Use-Case-Usage includes estimated_time_to_regain_access in minutes. For publishing, query GET /<IG_ID>/content_publishing_limit before you post. Our Instagram API pricing and limits post has the full list.
How do I keep Instagram API access from getting blocked again?#
Most of it is upkeep on the app and the tokens.
- Keep the contact email current. Enforcement and renewal notices go there.
- Turn on developer alerts. They're the other place Meta notifies you.
- Request only what you use. Every extra permission is another one you have to justify to Meta.
- Refresh every token on a schedule. Alert on 190s per account.
- Log error codes and subcodes. "Access blocked" in your logs tells you nothing;
25 / 2207050tells you exactly who to email. - Watch the usage headers. Slow down before you reach 100%.
Is there a way to avoid managing Meta access yourself?#
Yes. Build on an API that already holds the Meta app. Adeli maintains the developer app on every supported network, completes each platform's review process, and manages OAuth connections and token refresh, so your team never registers its own Meta app.
- One API key. Your team holds one key instead of a Meta developer app.
- Your users' own accounts. Each user connects their own Instagram account through Adeli.
- Clear failures. Account-level problems, like a personal account or an Instagram restriction, still belong to the account. Adeli returns a per-platform status and fires a webhook when anything changes, so you can show the user the actual problem.
- More than Instagram. The same posting API publishes to Instagram, TikTok, YouTube, Facebook, and X.
On Adeli's pricing, your first 3 connected accounts are free, with no credit card.